
(For a video version of my introductory comments, click here.)
Hello all,
This has been an interesting week with the variety of severe vulnerabilities reported, and the types and numbers of breached or compromised organizations, some of which are massive.
Headline NEWS:
- Broadcom has released updates to VMware Tools for Windows to address an authentication bypass defect. Immediate updates are urged to plug this hole.
- CrushFTP emailed all clients a week ago to update to their latest version to plug a hole that allows for unauthenticated access. It has not been reported as exploited in the wild yet, but now that it is being reported publicly, that’s only a matter of time.
- Google released another update for a zero-day defect in their Chrome browser. Interestingly, this one was brought to them by a Russian researcher who was looking to have attacks against Russia via the hole stopped. Other chromium browsers, such as Microsoft Edge, have been pushing updates for this defect too.
- Mozilla Firefox developers examined the defect that Google patched and discovered that they were also vulnerable. As a result, apply the latest Firefox update to plug a critical sandbox escape defect as soon as possible.
- HaveIBeenPwned is a website that houses a gargantuan database of email addresses that have been compromised. It is owned and maintained by Troy Hunt. He was just Pwned via a phishing email purporting to be his mailing list vendor, MailChimp. Troy’s blog about this event goes into excellent detail about how this happened and offers advice to others to avoid his error.
- IngressNightmare is the moniker given to a series of vulnerabilities found in the “Ingress NGINX Controller” for Kubernetes. This one is critical as it allows for remote code execution without authentication. If you use this, patch immediately!
- Next.js has a major hole that looks like it could be another Log4J or Log4Shell type of vulnerability. If you’ve used this in your programming or environment, update to the latest version to fix this. The rest of us need to watch for updates from our vendors to ensure that this is properly patched. We all know which of our software this is because they all have a Software Bill of Materials (SBOM) listing all dependencies contained therein, right?
- Oracle has apparently experienced two separate breaches recently. The first involves a criminal dirtbag that goes by the moniker “rose87168” who claims to have exfiltrated 6 million records, impacting in excess of 140,000 tenants from Oracle’s Cloud service. For their part, Oracle is denying the report and claims there has been no breach, despite mounting evidence from various security researchers, and confirmation from victim organizations that leaked sample data is in indeed genuine. The second breach, which Bloomberg reported is being investigated by the FBI, that is not being currently denied or acknowledged is in Oracle Health. This breach was apparently in older servers that had not yet been migrated to Oracle’s Cloud. There are reports of Oracle privately contacting impacted organizations and telling them that they’ll help identify impacted victims, but it is up to the hospitals to determine if they are subject to any HIPAA regulations. Obviously, both of these breaches will have far-reaching implications for impacted organizations and individuals.
In Ransomware, Malware, and Vulnerabilities News:
- Walmart and WOW are both investigating claims by evil individuals that they’ve successfully attacked and exfiltrated troves of data from them. Walmart’s alleged breach is in SAMS Club, with the group Cl0p claiming credit. As yet there is no evidence presented, nor is there confirmation from Walmart. Since Cl0p was heavily involved in the recent Cleo file transfer platform vulnerability and breach, it is highly possible that it is the source of this event. The WOW breach is claimed by a Russian speaking group with the moniker Arkana. They assert that they have accessed over 400,000 client records and have control over WOW’s backend infrastructure. Their announcement contained an evilly creative music video showing off some of their claims, so this is likely going to get ugly fast.
In Other News Events of Note and Interest:
- Anthropic scientists expose how AI actually ‘thinks’ is a fascinating dive into the “black box” of what happens between when an AI is given an input and the output it creates. How does it do what it does is a question that is only partially understood, and in many cases, it was not what the researchers expected.
Musings:
Those of us who have grown up with digital everything are part of what I suspect will be a “lost generation” a hundred years from now. We are memorializing our experiences in digital format. And while this is an excellent way to preserve them for future generations, it is not an ideal medium for presentation. We used to carefully curate selected photos to represent events or interests. Now we have massive, often random collections of digital images and communication. We used to keep shoe boxes or file folders of correspondence. We had flip out albums full of photos and handwritten notes about vacations, weddings, birthdays and more. You could touch, feel, smell and interact with the printed page that just doesn’t have the same tactile fondness and feeling of sentiment when presented by cold electrons. How do you press a flower or leaf into the pages of your iPad? Where do you store that lock of hair? Do you have photo albums you can pass on to future generations? How about hard copies of letters or notes that have been sent by or to you? Sure, if these exist in digital format, ensure that you hold onto copies of them. However, I encourage you to think about also preserving these in hard copy format. Future generations will thank you.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Broadcom warns of authentication bypass in VMware Windows Tools
- Update VMware Tools for Windows NOW: High-Severity Flaw Lets Hackers Bypass Authentication
- CrushFTP warns users to patch unauthenticated access flaw immediately
- Update now! Chrome patches ‘high risk’ zero-day security flaw on PCs
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks
- Mozilla warns Windows users of critical Firefox sandbox escape flaw
- Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish
- Troy Hunt: A Sneaky Phish Just Grabbed my Mailchimp Mailing List
- Ingress NGINX Controller for Kubernetes, collectively known as IngressNightmare
- Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
- js Middleware Authorization Bypass Vulnerability
- Oracle Denies Claim of Oracle Cloud Breach of 6M Records
- There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial
- Security Firms Say Evidence Seems to Confirm Oracle Cloud Hack
- Oracle customers confirm data stolen in alleged cloud breach is valid
- Threat actor in Oracle Cloud breach may have gained access to production environments
- Cybersecurity firms brace for impact of potential Oracle Cloud breach
Ransomware, Malware, and Vulnerabilities News
- CISA Adds of Sitecore CMS Code Execution Vulnerability to List of Known Exploited Vulnerabilities
- INTERPOL Arrests 306 Suspects, Seizes 1,842 Devices in Cross-Border Cybercrime Bust
- Accused Snowflake Attacker ‘Judische’ Agrees to US Extradition
- Security shop pwns ransomware gang, passes insider info to authorities
- US Consumers Lose $2,088,000,000 to Fraudulent Bank Transfers and Payments, According to FTC
- 23andMe faces an uncertain future — so does your genetic data
- DNA testing company 23andMe wins court approval to sell data after it filed for bankruptcy.
- 23andMe Bankruptcy: Company says issue with customers being unable to delete their data has now been resolved
- Over 3 million applicants’ data leaked on NYU’s website
- Dozens of solar inverter flaws could be exploited to attack power grids
- Days after the Signal leak, the Pentagon warned the app was the target of hackers
- CrushFTP CEO’s feisty response to VulnCheck’s CVE for critical make-me-admin bug
- Splunk RCE Vulnerability Let Attackers Execute Arbitrary Code Via File Upload
- Browser-in-the-Browser attacks target CS2 players’ Steam accounts
- New Atlantis AIO platform automates credential stuffing on 140 services
- New Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims’ DNS Email Records
- ‘Lucid’ Phishing Tool Exploits Faults in iMessage, RCS
- CoffeeLoader Uses GPU-Based Armoury Packer to Evade EDR and Antivirus Detection
- Hackers Deliver Malware via Browser Extensions & Legitimate Tools to Bypass Security Controls
- Hijacked Microsoft Stream classic domain “spams” SharePoint sites
- Microsoft Trusted Signing service abused to code-sign malware
- Hackers Exploit Windows MMC Zero-Day Vulnerability to Execute Malicious Code
- EncryptHub linked to MMC zero-day attacks on Windows systems
- New Windows zero-day leaks NTLM hashes, gets unofficial patch
- FBI warnings are true—fake file converters do push malware
- 11 ways cybercriminals are making phishing more potent than ever
- Cybercriminals are Spreading Malware to Microsoft 365 Accounts via Fake Apps (Again)
- Chinese hackers are getting bigger, better and stealthier
- As nation-state hacking becomes ‘more in your face,’ are supply chains secure?
- Oracle Health breach compromises patient data at US hospitals
- Walmart Investigating Clop Ransomware Claims of Sam’s Club Data Breach
- Arkana Ransomware Attack on WideOpenWest: What You Need to Know
- Cyber-crew claims it cracked American cableco, releases terrible music video to prove it
- Cybercrime Gang Says It Hacked This US ISP, Stole Info on 403K Customers
- Chinese Weaver Ant hackers spied on telco network for 4 years
- Researchers Uncover ~200 Unique C2 Domains Linked to Raspberry Robin Access Broker
- Ontinue Research Reveals Ransomware Attacks Surged 132% Despite 35% Drop in Payments
- New VanHelsing ransomware targets Windows, ARM, ESXi systems
- Albabat Ransomware Expands Targets, Abuses GitHub
- Albabat Ransomware Evolves to Target Linux and macOS
- RedCurl cyberspies create ransomware to encrypt Hyper-V servers
- EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware
- Kuala Lumpur Airport Hit by Cyberattack, Hackers Demand $10M Ransom
- Hackers steal sensitive data from Pennsylvania county during ransomware attack
- Cybersecurity specialists are drowning in a sea of software vulnerabilities. AI may be able to help
- Space Pirates Are No Longer Confined To Works Of Science Fiction
- Atlanta airport stops potential cyberattack Friday morning
Other News Events of Note and Interest
- Cool Tool: EarTrumpet makes adjusting individual app volumes simple
- Anthropic scientists expose how AI actually ‘thinks’ — and discover it secretly plans ahead and sometimes lies
- Tracing the thoughts of a large language model
- OpenAI Offering $100K Bounties for Critical Vulnerabilities
- Apple barred from Google antitrust trial, putting $20 billion search deal on the line
- Google Chrome ‘can’t run’ on Windows due to broken install tool
- Google rolls out new vacation-planning features to Search, Maps, and Gemini
- Broadcom raises minimum requirement for VMware licenses: from 16 to 72 cores
- DrayTek routers worldwide go into reboot loops over weekend
- INL collaborates with Florida to protect water infrastructure from cyber threats
- Samsung promises to repair soundbars bricked by its disastrous software update for free – but it’ll probably involve shipping
- Trump shifts cyberattack readiness to state and local governments in wake of info-sharing cuts
- Vivaldi bakes Proton VPN into browser to boost privacy
- Is your Windows PC’s security firewall good enough? An explainer
- Microsoft Teams is finally adding a tiny but crucial feature I honestly can’t believe it never had
- Microsoft releases mandatory Windows 10 update with installation failures and bugs
- Microsoft unveils Microsoft Security Copilot agents and new protections for AI
- Microsoft begins default-deploying New Outlook for Windows on Microsoft 365
- Microsoft “confirms” it still won’t let users update to Windows 11 24H2 due to audio bug
- Microsoft releases Windows 11 22H2/23H2 KB5053657 with new features and improvements
- Windows 10 KB5053643 is out with fixes for File Explorer, Remote Desktop, and more
- Windows 11 update breaks Veeam recovery, causes connection errors
- Microsoft: Recent Windows updates cause Remote Desktop issues
- Microsoft’s account sign-in UI gets a new design and dark mode
- Microsoft Moves 63,000 UK Home Office Users to Teams Phone in Just 8 Days
- Microsoft 365 bringing performance boost to Office apps like Word, Outlook, Excel
- Microsoft Recent Windows Server 2025 updates cause Remote Desktop freezes
- Windows 11’s latest patch declares war on BIOS updates for some Lenovo laptops, blocking them as a security risk in a bizarre turn of events
- Microsoft reveals new Windows roadmap for feature availability